Check Username/Password
POST {{authPath}}/{{envID}}/flows/{{flowID}}
The POST /{{envID}}/flows/{{flowID}} operation initiates an action to allow users to login with a username and password. The request body requires the username and password attributes. The values for these properties provided by the user are verified in this action. This operation uses the application/vnd.pingidentity.usernamePassword.check+json custom media type as the content type in the request header.
Prerequisites
-
Refer to Flows for important overview information.
-
Send an authorize request to get a flow ID: Authorize. Refer also to Login action authentication flow and Authorization and authentication.
-
Start the flow: Read Flow.
-
Refer also to the
USERNAME_PASSWORD_REQUIREDandACCOUNT_LINKING_REQUIREDflow states in the Flow status values table.
If there is a user already associated with the current flow, and a username value is provided in the request body, then the value of username must identify the user associated with the session.
In the response data, the status property value indicates that the one-time password validation step used in a multi-factor authentication flow is a required action. The validateOTP link to initiate this required step is also included in the response.
|
This action is also used with the |
Request Model
| Property | Type | Required? |
|---|---|---|
|
String |
Required |
|
String |
Required |
Example Request
-
cURL
-
C#
-
Go
-
HTTP
-
Java
-
jQuery
-
NodeJS
-
Python
-
PHP
-
Ruby
-
Swift
curl --location --globoff '{{authPath}}/{{envID}}/flows/{{flowID}}' \
--header 'Content-Type: application/vnd.pingidentity.usernamePassword.check+json' \
--data '{
"username": "{{email}}",
"password": "{{userPassword}}"
}'
var options = new RestClientOptions("{{authPath}}/{{envID}}/flows/{{flowID}}")
{
MaxTimeout = -1,
};
var client = new RestClient(options);
var request = new RestRequest("", Method.Post);
request.AddHeader("Content-Type", "application/vnd.pingidentity.usernamePassword.check+json");
var body = @"{" + "\n" +
@" ""username"": ""{{email}}""," + "\n" +
@" ""password"": ""{{userPassword}}""" + "\n" +
@"}";
request.AddStringBody(body, DataFormat.Json);
RestResponse response = await client.ExecuteAsync(request);
Console.WriteLine(response.Content);
package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "{{authPath}}/{{envID}}/flows/{{flowID}}"
method := "POST"
payload := strings.NewReader(`{
"username": "{{email}}",
"password": "{{userPassword}}"
}`)
client := &http.Client {
}
req, err := http.NewRequest(method, url, payload)
if err != nil {
fmt.Println(err)
return
}
req.Header.Add("Content-Type", "application/vnd.pingidentity.usernamePassword.check+json")
res, err := client.Do(req)
if err != nil {
fmt.Println(err)
return
}
defer res.Body.Close()
body, err := io.ReadAll(res.Body)
if err != nil {
fmt.Println(err)
return
}
fmt.Println(string(body))
}
POST /{{envID}}/flows/{{flowID}} HTTP/1.1
Host: {{authPath}}
Content-Type: application/vnd.pingidentity.usernamePassword.check+json
{
"username": "{{email}}",
"password": "{{userPassword}}"
}
OkHttpClient client = new OkHttpClient().newBuilder()
.build();
MediaType mediaType = MediaType.parse("application/vnd.pingidentity.usernamePassword.check+json");
RequestBody body = RequestBody.create(mediaType, "{\n \"username\": \"{{email}}\",\n \"password\": \"{{userPassword}}\"\n}");
Request request = new Request.Builder()
.url("{{authPath}}/{{envID}}/flows/{{flowID}}")
.method("POST", body)
.addHeader("Content-Type", "application/vnd.pingidentity.usernamePassword.check+json")
.build();
Response response = client.newCall(request).execute();
var settings = {
"url": "{{authPath}}/{{envID}}/flows/{{flowID}}",
"method": "POST",
"timeout": 0,
"headers": {
"Content-Type": "application/vnd.pingidentity.usernamePassword.check+json"
},
"data": JSON.stringify({
"username": "{{email}}",
"password": "{{userPassword}}"
}),
};
$.ajax(settings).done(function (response) {
console.log(response);
});
var request = require('request');
var options = {
'method': 'POST',
'url': '{{authPath}}/{{envID}}/flows/{{flowID}}',
'headers': {
'Content-Type': 'application/vnd.pingidentity.usernamePassword.check+json'
},
body: JSON.stringify({
"username": "{{email}}",
"password": "{{userPassword}}"
})
};
request(options, function (error, response) {
if (error) throw new Error(error);
console.log(response.body);
});
import requests
import json
url = "{{authPath}}/{{envID}}/flows/{{flowID}}"
payload = json.dumps({
"username": "{{email}}",
"password": "{{userPassword}}"
})
headers = {
'Content-Type': 'application/vnd.pingidentity.usernamePassword.check+json'
}
response = requests.request("POST", url, headers=headers, data=payload)
print(response.text)
<?php
require_once 'HTTP/Request2.php';
$request = new HTTP_Request2();
$request->setUrl('{{authPath}}/{{envID}}/flows/{{flowID}}');
$request->setMethod(HTTP_Request2::METHOD_POST);
$request->setConfig(array(
'follow_redirects' => TRUE
));
$request->setHeader(array(
'Content-Type' => 'application/vnd.pingidentity.usernamePassword.check+json'
));
$request->setBody('{\n "username": "{{email}}",\n "password": "{{userPassword}}"\n}');
try {
$response = $request->send();
if ($response->getStatus() == 200) {
echo $response->getBody();
}
else {
echo 'Unexpected HTTP status: ' . $response->getStatus() . ' ' .
$response->getReasonPhrase();
}
}
catch(HTTP_Request2_Exception $e) {
echo 'Error: ' . $e->getMessage();
}
require "uri"
require "json"
require "net/http"
url = URI("{{authPath}}/{{envID}}/flows/{{flowID}}")
http = Net::HTTP.new(url.host, url.port);
request = Net::HTTP::Post.new(url)
request["Content-Type"] = "application/vnd.pingidentity.usernamePassword.check+json"
request.body = JSON.dump({
"username": "{{email}}",
"password": "{{userPassword}}"
})
response = http.request(request)
puts response.read_body
let parameters = "{\n \"username\": \"{{email}}\",\n \"password\": \"{{userPassword}}\"\n}"
let postData = parameters.data(using: .utf8)
var request = URLRequest(url: URL(string: "{{authPath}}/{{envID}}/flows/{{flowID}}")!,timeoutInterval: Double.infinity)
request.addValue("application/vnd.pingidentity.usernamePassword.check+json", forHTTPHeaderField: "Content-Type")
request.httpMethod = "POST"
request.httpBody = postData
let task = URLSession.shared.dataTask(with: request) { data, response, error in
guard let data = data else {
print(String(describing: error))
return
}
print(String(data: data, encoding: .utf8)!)
}
task.resume()
Example Response
200 OK
{
"_links": {
"self": {
"href": "https://auth.pingone.com/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/flows/03e52d0a-c55a-4807-889b-cd14f74ec4c5"
}
},
"id": "03e52d0a-c55a-4807-889b-cd14f74ec4c5",
"session": {
"id": "5655baab-c282-4f9d-8d01-b635fe66b528"
},
"resumeUrl": "https://auth.pingone.com/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/as/resume?flowId=03e52d0a-c55a-4807-889b-cd14f74ec4c5",
"status": "COMPLETED",
"createdAt": "2021-07-23T16:19:34.570Z",
"expiresAt": "2021-07-23T16:34:53.196Z",
"_embedded": {
"user": {
"id": "831441df-b71f-473c-8871-c0af518ad851",
"username": "app_user_1627057164",
"name": {
"given": "Test",
"family": "ApplicationUser"
}
},
"application": {
"name": "Single-Page-App_1627057132"
}
}
}